CVE-2026-16778 | Live Composer Plugin up to 2.1.21 on WordPress Shortcode shortcode callback cross site scripting

SecurityVulns

A vulnerability has been found in Live Composer Plugin up to 2.1.21 on WordPress and classified as problematic. Impacted is the function shortcode callback of the component Shortcode Handler. Performing a manipulation of the argument view_all_link/main_heading_title/button_text/button_inline_svg results in cross site scripting.

This vulnerability is cataloged as CVE-2026-16778. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More